logo

Microsoft: Critical Security Issue Found in Windows Notepad

ID: 5c8e7b04-f55e-5aea-8468-0e36f2edf045

STIX ID: report--5c8e7b04-f55e-5aea-8468-0e36f2edf045

Feed Name: TechRepublic Security

Threat Score
55/100

Date Published: 2026-02-20

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

Microsoft patched CVE-2026-20841, a high-severity remote code execution vulnerability in the modern Notepad app's Markdown/link handling: a specially crafted .md file and a clicked link can execute code with the user's privileges. Exploitation requires user interaction, the legacy Notepad is unaffected, a patch was released in February 2026, and proof-of-concept code exists though no widespread exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.